Messaging app Tokee may have leaked 1.2 million user profiles. Experts say exposed personal data “poses significant privacy, security and regulatory risks.”


  • Cybernews discovered that Tokee’s unprotected MongoDB exposed the data of around 1.2 million users
  • The leak included names, phone numbers, avatars, device tokens, identifiers, activity logs, and account status; chat logs were encrypted
  • Deucetek secured the database after its disclosure; no evidence of malicious access, but users warned of phishing risks

A messaging app called Tokee kept an unprotected database containing lots of sensitive information, exposing more than a million customers to anyone who knew where to look.

Security researchers from Cybernews discovered a non-password-protected MongoDB instance that contained users’ display names, phone numbers stored as numeric values, profile avatars, device tokens used for push notifications, user IDs, timestamps for account creation and update, “last seen” activity indicators, and account status indicators (e.g., premium or non-premium).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top